Everything you need for institutional diligence.
Security, compliance and regulatory information in one place — presented honestly, with verified credentials and transparent status on what is in progress.
Built like critical infrastructure
Defense in depth, least-privilege access and full auditability, with embedded risk screening on every transaction.
Infrastructure & monitoringCredentials & certifications
We publish only what is verified and mark what is in progress.
FINTRAC MSB
FLOWA PAY INC., Canada. Reg. no. C100000902.
PCI DSS
Attestation targeted pre-launch.
SOC 2 · ISO 27001
Independent audit planned.
GDPR
Privacy-by-design data handling.
The questions institutions ask first
Answered here rather than after three rounds of email. Where something is in progress we say so, and where a question is answered by a published policy we link straight to it.
What is your regulatory status?
FLOWA PAY INC. is registered with FINTRAC as a money services business, registration C100000902, verifiable on the public registry. That is a registration, not a licence, approval or endorsement, and not a banking, e-money or acquiring licence.
Who performs the acquiring?
Licensed acquiring and payment partners, under their own authorisations. Flowa Pay provides the technology and orchestration layer, and is not the acquirer.
How is card data handled?
Captured in a Flowa Pay-controlled payment surface and exchanged for a token on hosted and embedded integrations, so card numbers do not rest in merchant systems. The card-data environment is segmented and engineered to PCI DSS; formal attestation is in progress.
What are your security controls?
Encryption in transit and at rest, role-based least-privilege access, multi-factor authentication, signed webhooks, request validation, continuous monitoring and a documented incident-response process. The security page sets each one out.
How do you handle personal data?
Privacy-by-design handling with data minimisation, defined retention and documented processing bases, set out in the Privacy Policy, GDPR and Data Protection pages.
How do you onboard merchants?
Risk-based KYC and KYB with ultimate beneficial ownership verification, sanctions, PEP and adverse-media screening, a documented decision and ongoing monitoring proportionate to risk.
What happens in an incident?
Defined severities, escalation paths, direct notification of affected account contacts, and a written post-incident review for material incidents. Continuity and recovery are covered by published policies.
Can you support our audit?
Yes. Policies are published rather than gated, and further material for an institutional review can be requested through the contact page.
What are you not claiming?
We publish no certification we do not hold, no customer names without written consent, no partner names we are not permitted to state, and no metrics we cannot evidence.
The full compliance library
Financial crime, risk, governance, data protection and operational resilience policies are published in full and linked from one index.
Request our diligence pack
Tell us what your review needs and we will send the security overview and compliance summary.